diff --git a/advisories/unreviewed/2024/11/GHSA-2794-6m94-77f7/GHSA-2794-6m94-77f7.json b/advisories/unreviewed/2024/11/GHSA-2794-6m94-77f7/GHSA-2794-6m94-77f7.json index 03a15a62c91..8c323b50f65 100644 --- a/advisories/unreviewed/2024/11/GHSA-2794-6m94-77f7/GHSA-2794-6m94-77f7.json +++ b/advisories/unreviewed/2024/11/GHSA-2794-6m94-77f7/GHSA-2794-6m94-77f7.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-4gvm-v69v-r798/GHSA-4gvm-v69v-r798.json b/advisories/unreviewed/2024/11/GHSA-4gvm-v69v-r798/GHSA-4gvm-v69v-r798.json new file mode 100644 index 00000000000..6369318e979 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4gvm-v69v-r798/GHSA-4gvm-v69v-r798.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4gvm-v69v-r798", + "modified": "2024-11-18T15:33:20Z", + "published": "2024-11-18T15:33:20Z", + "aliases": [ + "CVE-2024-11304" + ], + "details": "Missing input validation in the SEH Computertechnik utnserver Pro, SEH Computertechnik utnserver ProMAX, SEH Computertechnik INU-100 web-interface allows stored Cross-Site Scripting (XSS). This issue affects utnserver Pro, utnserver ProMAX, INU-100 version 20.1.22 and below.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11304" + }, + { + "type": "WEB", + "url": "https://cyberdanube.com/en/en-st-polten-uas-stored-cross-site-scripting-in-seh-utnserver-pro/index.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T15:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5wm2-wm6h-c24c/GHSA-5wm2-wm6h-c24c.json b/advisories/unreviewed/2024/11/GHSA-5wm2-wm6h-c24c/GHSA-5wm2-wm6h-c24c.json new file mode 100644 index 00000000000..63dba7b76c6 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5wm2-wm6h-c24c/GHSA-5wm2-wm6h-c24c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5wm2-wm6h-c24c", + "modified": "2024-11-18T15:33:21Z", + "published": "2024-11-18T15:33:21Z", + "aliases": [ + "CVE-2024-52431" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pressaholic WordPress Video Robot - The Ultimate Video Importer allows SQL Injection.This issue affects WordPress Video Robot - The Ultimate Video Importer: from n/a through 1.20.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52431" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-video-robot/wordpress-wp-video-robot-plugin-1-20-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T15:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6pgp-m34x-gm73/GHSA-6pgp-m34x-gm73.json b/advisories/unreviewed/2024/11/GHSA-6pgp-m34x-gm73/GHSA-6pgp-m34x-gm73.json new file mode 100644 index 00000000000..42f7fc6245c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6pgp-m34x-gm73/GHSA-6pgp-m34x-gm73.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6pgp-m34x-gm73", + "modified": "2024-11-18T15:33:21Z", + "published": "2024-11-18T15:33:21Z", + "aliases": [ + "CVE-2024-52430" + ], + "details": "Deserialization of Untrusted Data vulnerability in Lis Lis Video Gallery allows Object Injection.This issue affects Lis Video Gallery: from n/a through 0.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52430" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/lis-video-gallery/wordpress-lis-video-gallery-plugin-0-2-1-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T15:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6xcf-fg99-v7c5/GHSA-6xcf-fg99-v7c5.json b/advisories/unreviewed/2024/11/GHSA-6xcf-fg99-v7c5/GHSA-6xcf-fg99-v7c5.json new file mode 100644 index 00000000000..059b73989b0 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6xcf-fg99-v7c5/GHSA-6xcf-fg99-v7c5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6xcf-fg99-v7c5", + "modified": "2024-11-18T15:33:21Z", + "published": "2024-11-18T15:33:21Z", + "aliases": [ + "CVE-2024-52428" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Scripteo Ads Booster by Ads Pro allows PHP Local File Inclusion.This issue affects Ads Booster by Ads Pro: from n/a through 1.12.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52428" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/free-wp-booster-by-ads-pro/wordpress-ads-booster-by-ads-pro-plugin-1-12-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T15:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-95mq-85gw-2hf3/GHSA-95mq-85gw-2hf3.json b/advisories/unreviewed/2024/11/GHSA-95mq-85gw-2hf3/GHSA-95mq-85gw-2hf3.json new file mode 100644 index 00000000000..54ec84ba3fc --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-95mq-85gw-2hf3/GHSA-95mq-85gw-2hf3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-95mq-85gw-2hf3", + "modified": "2024-11-18T15:33:21Z", + "published": "2024-11-18T15:33:21Z", + "aliases": [ + "CVE-2024-52433" + ], + "details": "Deserialization of Untrusted Data vulnerability in Mindstien Technologies My Geo Posts Free allows Object Injection.This issue affects My Geo Posts Free: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52433" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/my-geo-posts-free/wordpress-my-geo-posts-free-plugin-1-2-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-c9gx-rq5w-8v24/GHSA-c9gx-rq5w-8v24.json b/advisories/unreviewed/2024/11/GHSA-c9gx-rq5w-8v24/GHSA-c9gx-rq5w-8v24.json new file mode 100644 index 00000000000..aa09fa212d1 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-c9gx-rq5w-8v24/GHSA-c9gx-rq5w-8v24.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c9gx-rq5w-8v24", + "modified": "2024-11-18T15:33:21Z", + "published": "2024-11-18T15:33:21Z", + "aliases": [ + "CVE-2024-52436" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Post SMTP allows Blind SQL Injection.This issue affects Post SMTP: from n/a through 2.9.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52436" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/post-smtp/wordpress-post-smtp-plugin-2-9-9-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-f632-9449-3j4w/GHSA-f632-9449-3j4w.json b/advisories/unreviewed/2024/11/GHSA-f632-9449-3j4w/GHSA-f632-9449-3j4w.json new file mode 100644 index 00000000000..efb32d9533e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-f632-9449-3j4w/GHSA-f632-9449-3j4w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f632-9449-3j4w", + "modified": "2024-11-18T15:33:20Z", + "published": "2024-11-18T15:33:20Z", + "aliases": [ + "CVE-2024-52318" + ], + "details": "Incorrect object recycling and reuse vulnerability in Apache Tomcat.\n\nThis issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.96.\n\nUsers are recommended to upgrade to version 11.0.1, 10.1.32 or 9.0.97, which fixes the issue.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52318" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/co243cw1nlh6p521c5265cm839wkqdp9" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T13:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-g79m-w87v-w7c8/GHSA-g79m-w87v-w7c8.json b/advisories/unreviewed/2024/11/GHSA-g79m-w87v-w7c8/GHSA-g79m-w87v-w7c8.json index d06836fcc6a..89026f8149f 100644 --- a/advisories/unreviewed/2024/11/GHSA-g79m-w87v-w7c8/GHSA-g79m-w87v-w7c8.json +++ b/advisories/unreviewed/2024/11/GHSA-g79m-w87v-w7c8/GHSA-g79m-w87v-w7c8.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-h53w-2cq3-cj2p/GHSA-h53w-2cq3-cj2p.json b/advisories/unreviewed/2024/11/GHSA-h53w-2cq3-cj2p/GHSA-h53w-2cq3-cj2p.json new file mode 100644 index 00000000000..9636f06ca28 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-h53w-2cq3-cj2p/GHSA-h53w-2cq3-cj2p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h53w-2cq3-cj2p", + "modified": "2024-11-18T15:33:21Z", + "published": "2024-11-18T15:33:21Z", + "aliases": [ + "CVE-2024-52427" + ], + "details": "Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Saso Nikolov Event Tickets with Ticket Scanner allows Server Side Include (SSI) Injection.This issue affects Event Tickets with Ticket Scanner: from n/a through 2.3.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52427" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/event-tickets-with-ticket-scanner/wordpress-event-tickets-with-ticket-scanner-plugin-2-3-11-remote-code-execution-rce-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1336" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T15:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jm35-qh64-mx86/GHSA-jm35-qh64-mx86.json b/advisories/unreviewed/2024/11/GHSA-jm35-qh64-mx86/GHSA-jm35-qh64-mx86.json new file mode 100644 index 00000000000..d17917eca99 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jm35-qh64-mx86/GHSA-jm35-qh64-mx86.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jm35-qh64-mx86", + "modified": "2024-11-18T15:33:21Z", + "published": "2024-11-18T15:33:21Z", + "aliases": [ + "CVE-2024-52432" + ], + "details": "Deserialization of Untrusted Data vulnerability in NIX Solutions Ltd NIX Anti-Spam Light allows Object Injection.This issue affects NIX Anti-Spam Light: from n/a through 0.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52432" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/nix-anti-spam-light/wordpress-nix-anti-spam-light-plugin-0-0-4-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T15:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mh9h-44jv-cw34/GHSA-mh9h-44jv-cw34.json b/advisories/unreviewed/2024/11/GHSA-mh9h-44jv-cw34/GHSA-mh9h-44jv-cw34.json index e7714d86c80..f4bc01ca5d4 100644 --- a/advisories/unreviewed/2024/11/GHSA-mh9h-44jv-cw34/GHSA-mh9h-44jv-cw34.json +++ b/advisories/unreviewed/2024/11/GHSA-mh9h-44jv-cw34/GHSA-mh9h-44jv-cw34.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mh9h-44jv-cw34", - "modified": "2024-11-18T06:30:36Z", + "modified": "2024-11-18T15:33:20Z", "published": "2024-11-18T06:30:35Z", "aliases": [ "CVE-2024-43704" ], "details": "Software installed and run as a non-privileged user may conduct improper GPU system calls to gain access to the graphics buffers of a parent process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-668" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-18T05:15:04Z" diff --git a/advisories/unreviewed/2024/11/GHSA-mr84-jvj9-87g5/GHSA-mr84-jvj9-87g5.json b/advisories/unreviewed/2024/11/GHSA-mr84-jvj9-87g5/GHSA-mr84-jvj9-87g5.json index b090b504940..6b024db0943 100644 --- a/advisories/unreviewed/2024/11/GHSA-mr84-jvj9-87g5/GHSA-mr84-jvj9-87g5.json +++ b/advisories/unreviewed/2024/11/GHSA-mr84-jvj9-87g5/GHSA-mr84-jvj9-87g5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mr84-jvj9-87g5", - "modified": "2024-11-08T21:33:57Z", + "modified": "2024-11-18T15:33:19Z", "published": "2024-11-08T21:33:57Z", "aliases": [ "CVE-2024-44765" ], "details": "An Improper Authorization (Access Control Misconfiguration) vulnerability in MGT-COMMERCE GmbH v2.0.0 to v2.4.2 allows attackers to escalate privileges and access sensitive information via manipulation of the Nginx configuration file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-08T19:15:05Z" diff --git a/advisories/unreviewed/2024/11/GHSA-mrwr-hhwh-wjwq/GHSA-mrwr-hhwh-wjwq.json b/advisories/unreviewed/2024/11/GHSA-mrwr-hhwh-wjwq/GHSA-mrwr-hhwh-wjwq.json new file mode 100644 index 00000000000..b2292d8b6ea --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mrwr-hhwh-wjwq/GHSA-mrwr-hhwh-wjwq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mrwr-hhwh-wjwq", + "modified": "2024-11-18T15:33:20Z", + "published": "2024-11-18T15:33:20Z", + "aliases": [ + "CVE-2024-11318" + ], + "details": "An IDOR (Insecure Direct Object Reference) vulnerability has been discovered in AbsysNet, affecting version 2.3.1. This vulnerability could allow a remote attacker to obtain the session of an unauthenticated user by brute-force attacking the session identifier on the \"/cgi-bin/ocap/\" endpoint.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11318" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/idor-vulnerability-absysnet" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T14:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-phhx-m29g-px4m/GHSA-phhx-m29g-px4m.json b/advisories/unreviewed/2024/11/GHSA-phhx-m29g-px4m/GHSA-phhx-m29g-px4m.json new file mode 100644 index 00000000000..d414815749a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-phhx-m29g-px4m/GHSA-phhx-m29g-px4m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phhx-m29g-px4m", + "modified": "2024-11-18T15:33:20Z", + "published": "2024-11-18T15:33:20Z", + "aliases": [ + "CVE-2024-3370" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Egebilgi Software Website Template allows SQL Injection.This issue affects Website Template: before 29.04.2024.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3370" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-24-1860" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T13:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qg4j-v5g9-57ff/GHSA-qg4j-v5g9-57ff.json b/advisories/unreviewed/2024/11/GHSA-qg4j-v5g9-57ff/GHSA-qg4j-v5g9-57ff.json new file mode 100644 index 00000000000..361c5452b26 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qg4j-v5g9-57ff/GHSA-qg4j-v5g9-57ff.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qg4j-v5g9-57ff", + "modified": "2024-11-18T15:33:21Z", + "published": "2024-11-18T15:33:21Z", + "aliases": [ + "CVE-2024-28058" + ], + "details": "In RSA NetWitness (NW) Platform before 12.5.1, even when an administrator revokes the access of a specific user with an active session, an internal threat actor could impersonate the revoked user and gain unauthorized access to sensitive data.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28058" + }, + { + "type": "WEB", + "url": "https://community.netwitness.com/t5/netwitness-platform-online/tkb-p/netwitness-online-documentation" + }, + { + "type": "WEB", + "url": "https://community.netwitness.com/t5/netwitness-platform-product/nw-2024-06-netwitness-platform-broken-access-control/ta-p/719454" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T15:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qj8p-7c2x-55jf/GHSA-qj8p-7c2x-55jf.json b/advisories/unreviewed/2024/11/GHSA-qj8p-7c2x-55jf/GHSA-qj8p-7c2x-55jf.json new file mode 100644 index 00000000000..caeaa6c21df --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qj8p-7c2x-55jf/GHSA-qj8p-7c2x-55jf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qj8p-7c2x-55jf", + "modified": "2024-11-18T15:33:20Z", + "published": "2024-11-18T15:33:20Z", + "aliases": [ + "CVE-2024-11303" + ], + "details": "The pathname of the root directory to a Restricted Directory ('Path Traversal') vulnerability in Korenix JetPort 5601 allows Path Traversal.This issue affects JetPort 5601: through 1.2.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11303" + }, + { + "type": "WEB", + "url": "https://cyberdanube.com/en/en-st-polten-uas-path-traversal-in-korenix-jetport" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T14:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rm25-8wjq-c6qm/GHSA-rm25-8wjq-c6qm.json b/advisories/unreviewed/2024/11/GHSA-rm25-8wjq-c6qm/GHSA-rm25-8wjq-c6qm.json new file mode 100644 index 00000000000..05369f5fa74 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rm25-8wjq-c6qm/GHSA-rm25-8wjq-c6qm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rm25-8wjq-c6qm", + "modified": "2024-11-18T15:33:20Z", + "published": "2024-11-18T15:33:20Z", + "aliases": [ + "CVE-2024-9526" + ], + "details": "There exists a stored XSS Vulnerability in Kubeflow Pipeline View web UI. The Kubeflow Web UI allows to create new pipelines. When creating a new pipeline, it is possible to add a description. The description field allows html tags, which are not filtered properly. Leading to a stored XSS. We recommend upgrading past commit 930c35f1c543998e60e8d648ce93185c9b5dbe8d", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:U/V:D/RE:L/U:Green" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9526" + }, + { + "type": "WEB", + "url": "https://github.com/kubeflow/pipelines/pull/10315" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T14:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-v664-p69f-2qfg/GHSA-v664-p69f-2qfg.json b/advisories/unreviewed/2024/11/GHSA-v664-p69f-2qfg/GHSA-v664-p69f-2qfg.json index 6725ae7d6ce..e2a5cebbf21 100644 --- a/advisories/unreviewed/2024/11/GHSA-v664-p69f-2qfg/GHSA-v664-p69f-2qfg.json +++ b/advisories/unreviewed/2024/11/GHSA-v664-p69f-2qfg/GHSA-v664-p69f-2qfg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v664-p69f-2qfg", - "modified": "2024-11-18T06:30:36Z", + "modified": "2024-11-18T15:33:20Z", "published": "2024-11-18T06:30:36Z", "aliases": [ "CVE-2024-5030" ], "details": "The CM Table Of Contents WordPress plugin before 1.2.3 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin perform such action via a CSRF attack", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-18T06:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-v92q-j4x7-3wcc/GHSA-v92q-j4x7-3wcc.json b/advisories/unreviewed/2024/11/GHSA-v92q-j4x7-3wcc/GHSA-v92q-j4x7-3wcc.json new file mode 100644 index 00000000000..73ab01cf6f6 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-v92q-j4x7-3wcc/GHSA-v92q-j4x7-3wcc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v92q-j4x7-3wcc", + "modified": "2024-11-18T15:33:21Z", + "published": "2024-11-18T15:33:21Z", + "aliases": [ + "CVE-2024-52429" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Anton Hoelstad WP Quick Setup allows Upload a Web Shell to a Web Server.This issue affects WP Quick Setup: from n/a through 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52429" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-quick-setup/wordpress-wp-quick-setup-plugin-2-0-arbitrary-plugin-and-theme-installation-to-remote-code-execution-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T15:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vmmq-p5r9-qm38/GHSA-vmmq-p5r9-qm38.json b/advisories/unreviewed/2024/11/GHSA-vmmq-p5r9-qm38/GHSA-vmmq-p5r9-qm38.json new file mode 100644 index 00000000000..fdd5a48856e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vmmq-p5r9-qm38/GHSA-vmmq-p5r9-qm38.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vmmq-p5r9-qm38", + "modified": "2024-11-18T15:33:21Z", + "published": "2024-11-18T15:33:21Z", + "aliases": [ + "CVE-2024-52434" + ], + "details": "Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Supsystic Popup by Supsystic allows Command Injection.This issue affects Popup by Supsystic: from n/a through 1.10.29.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52434" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/popup-by-supsystic/wordpress-popup-by-supsystic-plugin-1-10-29-remote-code-execution-rce-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1336" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-w7p3-xj8f-2mq8/GHSA-w7p3-xj8f-2mq8.json b/advisories/unreviewed/2024/11/GHSA-w7p3-xj8f-2mq8/GHSA-w7p3-xj8f-2mq8.json new file mode 100644 index 00000000000..518e51dfa61 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-w7p3-xj8f-2mq8/GHSA-w7p3-xj8f-2mq8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7p3-xj8f-2mq8", + "modified": "2024-11-18T15:33:21Z", + "published": "2024-11-18T15:33:21Z", + "aliases": [ + "CVE-2024-52435" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in W3 Eden, Inc. Premium Packages allows SQL Injection.This issue affects Premium Packages: from n/a through 5.9.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52435" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wpdm-premium-packages/wordpress-premium-packages-sell-digital-products-securely-plugin-5-9-3-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wjjp-7863-326g/GHSA-wjjp-7863-326g.json b/advisories/unreviewed/2024/11/GHSA-wjjp-7863-326g/GHSA-wjjp-7863-326g.json index dfba4e484ac..d03b6eb15a3 100644 --- a/advisories/unreviewed/2024/11/GHSA-wjjp-7863-326g/GHSA-wjjp-7863-326g.json +++ b/advisories/unreviewed/2024/11/GHSA-wjjp-7863-326g/GHSA-wjjp-7863-326g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wjjp-7863-326g", - "modified": "2024-11-08T21:33:57Z", + "modified": "2024-11-18T15:33:19Z", "published": "2024-11-08T21:33:57Z", "aliases": [ "CVE-2024-50809" ], "details": "The theme.php file in SDCMS 2.8 has a command execution vulnerability that allows for the execution of system commands", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-08T21:15:20Z" diff --git a/advisories/unreviewed/2024/11/GHSA-x9xr-4q3h-r33w/GHSA-x9xr-4q3h-r33w.json b/advisories/unreviewed/2024/11/GHSA-x9xr-4q3h-r33w/GHSA-x9xr-4q3h-r33w.json new file mode 100644 index 00000000000..dddc6fefea6 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-x9xr-4q3h-r33w/GHSA-x9xr-4q3h-r33w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9xr-4q3h-r33w", + "modified": "2024-11-18T15:33:20Z", + "published": "2024-11-18T15:33:20Z", + "aliases": [ + "CVE-2024-8781" + ], + "details": "Execution with Unnecessary Privileges, : Improper Protection of Alternate Path vulnerability in TR7 Application Security Platform (ASP) allows Privilege Escalation, -Privilege Abuse.This issue affects Application Security Platform (ASP): v1.4.25.188.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8781" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-24-1861" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-250" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T14:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xwfr-c9rv-m6pp/GHSA-xwfr-c9rv-m6pp.json b/advisories/unreviewed/2024/11/GHSA-xwfr-c9rv-m6pp/GHSA-xwfr-c9rv-m6pp.json index e94d76cce07..45ffdcc3fc1 100644 --- a/advisories/unreviewed/2024/11/GHSA-xwfr-c9rv-m6pp/GHSA-xwfr-c9rv-m6pp.json +++ b/advisories/unreviewed/2024/11/GHSA-xwfr-c9rv-m6pp/GHSA-xwfr-c9rv-m6pp.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false,